Mandiant says suspected state hackers exploited a Citrix NetScaler zero-day for three weeks before it was detected
Dozens of organizations in North America and Europe were affected, and researchers have named the attackers' tools WHIPSHOT and SLAPSHOT.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
New details show the Citrix NetScaler zero-day attacks began well before they were confirmed. Mandiant researchers told CyberScoop that the earliest known exploitation of CVE-2026-88772 took place on September 3, more than three weeks before Citrix and researchers confirmed in-the-wild attacks late last week. Charles Carmakal, chief technology officer at Mandiant Consulting, wrote that the company is "aware of dozens of impacted organizations." He attributed the attacks to "advanced and suspected state-sponsored threat actors." According to Mandiant, affected organizations in North America and Europe span government, financial services, education, telecommunications, legal and professional services, and the firm expects more attacks. Security Affairs identifies WHIPSHOT and SLAPSHOT as the tools used in the active campaign. The flaw allows unauthenticated remote code execution on appliances that many organizations use as their network edge and remote-access gateway. With a gap of at least three weeks between first exploitation and detection, administrators who patched only recently should assume their appliances may already be compromised and look for signs of intrusion.